AWS EC2

The current AMIs for all Flatcar Container Linux channels and EC2 regions are listed below and updated frequently. Using CloudFormation is the easiest way to launch a cluster, but it is also possible to follow the manual steps at the end of the article. Questions can be directed to the Flatcar Container Linux Discord server or user mailing list .

At the end of the document there are instructions for deploying with Terraform.

Release retention time

After publishing, releases will remain available as public AMIs on AWS for 9 months. AMIs older than 9 months will be un-published in regular garbage collection sweeps. Please note that this will not impact existing AWS instances that use those releases. However, deploying new instances (e.g. in autoscaling groups pinned to a specific AMI) will not be possible after the AMI was un-published.

Choosing a channel

Flatcar Container Linux is designed to be updated automatically with different schedules per channel. You can disable this feature , although we don’t recommend it. Read the release notes for specific features and bug fixes.

The Stable channel should be used by production clusters. Versions of Flatcar Container Linux are battle-tested within the Beta and Alpha channels before being promoted. The current version is Flatcar Container Linux 4593.2.5.

View as json feed: amd64 arm64
EC2 Region AMI Type AMI ID CloudFormation
af-south-1 HVM (amd64) ami-0f206aa7dccdc76e8 Launch Stack
HVM (arm64) ami-0a09685b1d7556cca Launch Stack
ap-east-1 HVM (amd64) ami-012047e7776c7e8e3 Launch Stack
HVM (arm64) ami-00a06953952f87665 Launch Stack
ap-northeast-1 HVM (amd64) ami-04759e86f1ad7baa9 Launch Stack
HVM (arm64) ami-0d22f4820eb1418cb Launch Stack
ap-northeast-2 HVM (amd64) ami-0486580ca9184299c Launch Stack
HVM (arm64) ami-01acbe1a2c3da9f3e Launch Stack
ap-south-1 HVM (amd64) ami-040bd73c3f3c4c7ee Launch Stack
HVM (arm64) ami-02149824867723c71 Launch Stack
ap-southeast-1 HVM (amd64) ami-046fe16a000c8bd8a Launch Stack
HVM (arm64) ami-0e96f18e0b115d0ad Launch Stack
ap-southeast-2 HVM (amd64) ami-03260aae5b1812a7f Launch Stack
HVM (arm64) ami-05368af1e7f8d2aeb Launch Stack
ap-southeast-3 HVM (amd64) ami-088b64215fa40f75b Launch Stack
HVM (arm64) ami-0498278986f2bd6b5 Launch Stack
ca-central-1 HVM (amd64) ami-0a4d5a19ef34adf68 Launch Stack
HVM (arm64) ami-0a5252cd7a04d5f78 Launch Stack
eu-central-1 HVM (amd64) ami-059ac8a4633062ac5 Launch Stack
HVM (arm64) ami-08c9802f6bea999f2 Launch Stack
eu-north-1 HVM (amd64) ami-0076277b42e665d87 Launch Stack
HVM (arm64) ami-0e2df9a263f1929e8 Launch Stack
eu-south-1 HVM (amd64) ami-062e97ed5526c3272 Launch Stack
HVM (arm64) ami-0d4f812c03bb68c0d Launch Stack
eu-west-1 HVM (amd64) ami-0c54091b8bd552b2e Launch Stack
HVM (arm64) ami-09f53da9daaa04a0e Launch Stack
eu-west-2 HVM (amd64) ami-03c251fb6427fae35 Launch Stack
HVM (arm64) ami-08be636f24a21d79a Launch Stack
eu-west-3 HVM (amd64) ami-0564140a7e2d3d33b Launch Stack
HVM (arm64) ami-05deaa86c51bf87b8 Launch Stack
sa-east-1 HVM (amd64) ami-0d9b6be30bf43a554 Launch Stack
HVM (arm64) ami-016cb4d9909e36523 Launch Stack
us-east-1 HVM (amd64) ami-0fd55907279e3a71d Launch Stack
HVM (arm64) ami-030c1f8932f5f9099 Launch Stack
us-east-2 HVM (amd64) ami-038347b3662bba26b Launch Stack
HVM (arm64) ami-0ec730bb8bfaeb24b Launch Stack
us-west-1 HVM (amd64) ami-02c7e7a96736e7c58 Launch Stack
HVM (arm64) ami-0f8e3e95857af9549 Launch Stack
us-west-2 HVM (amd64) ami-0d016f0450922e6fe Launch Stack
HVM (arm64) ami-00ad0a205fd4b53fc Launch Stack

The Beta channel consists of promoted Alpha releases. The current version is Flatcar Container Linux 4757.1.0.

View as json feed: amd64 arm64
EC2 Region AMI Type AMI ID CloudFormation
af-south-1 HVM (amd64) ami-05d18bf45a617b82a Launch Stack
HVM (arm64) ami-0562a13664d556f4a Launch Stack
ap-east-1 HVM (amd64) ami-0f74d4228d0d499ad Launch Stack
HVM (arm64) ami-0c24706ac72f40d0e Launch Stack
ap-northeast-1 HVM (amd64) ami-09ad769cec1e5eedd Launch Stack
HVM (arm64) ami-0941dcdbc99d59d74 Launch Stack
ap-northeast-2 HVM (amd64) ami-0736ad6f4953c0d8e Launch Stack
HVM (arm64) ami-01b134b8e5fcd125b Launch Stack
ap-south-1 HVM (amd64) ami-0a4c6d8f48fa19e95 Launch Stack
HVM (arm64) ami-04ac26a7a71b52188 Launch Stack
ap-southeast-1 HVM (amd64) ami-0dc98fc666146a44d Launch Stack
HVM (arm64) ami-0466d53a1c5b2b0f1 Launch Stack
ap-southeast-2 HVM (amd64) ami-065d4b2132e5e3f9d Launch Stack
HVM (arm64) ami-0ef1ca5576499fd38 Launch Stack
ap-southeast-3 HVM (amd64) ami-0a2df077e59ba82c0 Launch Stack
HVM (arm64) ami-013427d3f9df88874 Launch Stack
ca-central-1 HVM (amd64) ami-0e2565e5646f1580c Launch Stack
HVM (arm64) ami-006279756284c859b Launch Stack
eu-central-1 HVM (amd64) ami-046bd20cae8b54214 Launch Stack
HVM (arm64) ami-09e09e74717bed86b Launch Stack
eu-north-1 HVM (amd64) ami-035f7b9a5aec75cf6 Launch Stack
HVM (arm64) ami-01af8d4441644cd22 Launch Stack
eu-south-1 HVM (amd64) ami-0addb20429b27584f Launch Stack
HVM (arm64) ami-0b06f876bc8bc7b77 Launch Stack
eu-west-1 HVM (amd64) ami-024abb5952cbff02b Launch Stack
HVM (arm64) ami-03600c88b4ef359a4 Launch Stack
eu-west-2 HVM (amd64) ami-0f29182177e7541f3 Launch Stack
HVM (arm64) ami-0a9e4c01be0853b1c Launch Stack
eu-west-3 HVM (amd64) ami-0d1015929c2d809ef Launch Stack
HVM (arm64) ami-0508385456ce41763 Launch Stack
sa-east-1 HVM (amd64) ami-0001eacef5061ff4a Launch Stack
HVM (arm64) ami-007869a9d89c92025 Launch Stack
us-east-1 HVM (amd64) ami-0488e9d90d3be7a46 Launch Stack
HVM (arm64) ami-0cc7b5c7a6bfe837b Launch Stack
us-east-2 HVM (amd64) ami-0b41d7c6774d28bb9 Launch Stack
HVM (arm64) ami-09bd6d9ec474541ac Launch Stack
us-west-1 HVM (amd64) ami-0319d2f89eb70e042 Launch Stack
HVM (arm64) ami-0c2e80ce112c21426 Launch Stack
us-west-2 HVM (amd64) ami-0d650e9c9c1d59c21 Launch Stack
HVM (arm64) ami-041ce6a382aed1f15 Launch Stack

The Alpha channel closely tracks master and is released frequently. The newest versions of system libraries and utilities will be available for testing. The current version is Flatcar Container Linux 4790.0.0.

View as json feed: amd64 arm64
EC2 Region AMI Type AMI ID CloudFormation
af-south-1 HVM (amd64) ami-0ada1de246d09a03d Launch Stack
HVM (arm64) ami-0f63631767a7c04f2 Launch Stack
ap-east-1 HVM (amd64) ami-0c6a32962d2d01641 Launch Stack
HVM (arm64) ami-0b8ae53cacf7e4989 Launch Stack
ap-northeast-1 HVM (amd64) ami-07a2a5883f3e7089a Launch Stack
HVM (arm64) ami-0b10cf78749ed09e9 Launch Stack
ap-northeast-2 HVM (amd64) ami-0f0a8e1210fa1d196 Launch Stack
HVM (arm64) ami-0642169484de7c969 Launch Stack
ap-south-1 HVM (amd64) ami-01f31f523a640d210 Launch Stack
HVM (arm64) ami-0e116d4c78bf890ba Launch Stack
ap-southeast-1 HVM (amd64) ami-0f1fbfaae4d88cade Launch Stack
HVM (arm64) ami-045d4ae22923a6bbe Launch Stack
ap-southeast-2 HVM (amd64) ami-0669390c282e91c5e Launch Stack
HVM (arm64) ami-03255b0845da86436 Launch Stack
ap-southeast-3 HVM (amd64) ami-0c3a4e7b76cf8af19 Launch Stack
HVM (arm64) ami-0bf23c066b91f428b Launch Stack
ca-central-1 HVM (amd64) ami-0a70a4478d545b51b Launch Stack
HVM (arm64) ami-040995ec124d65327 Launch Stack
eu-central-1 HVM (amd64) ami-09fda4dc89b8aa020 Launch Stack
HVM (arm64) ami-0f0f8a1514f70648a Launch Stack
eu-north-1 HVM (amd64) ami-036df824a7e51400e Launch Stack
HVM (arm64) ami-0f0cd9d353a7f3a92 Launch Stack
eu-south-1 HVM (amd64) ami-0b9892547641f1ed9 Launch Stack
HVM (arm64) ami-0c20bf5fc3a92921d Launch Stack
eu-west-1 HVM (amd64) ami-092e76f25f08c540d Launch Stack
HVM (arm64) ami-0d69ab334fa3ba100 Launch Stack
eu-west-2 HVM (amd64) ami-06316232684fc8875 Launch Stack
HVM (arm64) ami-0ebece2e379f24dbf Launch Stack
eu-west-3 HVM (amd64) ami-0e81c28855133d0ed Launch Stack
HVM (arm64) ami-0e0a11e9eaa3ff20b Launch Stack
sa-east-1 HVM (amd64) ami-01140ebc833dc1701 Launch Stack
HVM (arm64) ami-0844fff51b9de07e4 Launch Stack
us-east-1 HVM (amd64) ami-03a4fafc6e446f063 Launch Stack
HVM (arm64) ami-0961ec224f2347db0 Launch Stack
us-east-2 HVM (amd64) ami-06d9d26d2ede0cea4 Launch Stack
HVM (arm64) ami-01279f2e52f9c16f1 Launch Stack
us-west-1 HVM (amd64) ami-0033dcc4fa693b3e9 Launch Stack
HVM (arm64) ami-085883fa6330f7034 Launch Stack
us-west-2 HVM (amd64) ami-096e17386aa266317 Launch Stack
HVM (arm64) ami-01f1ec4781b78bc6d Launch Stack

LTS release streams are maintained for an extended lifetime of 18 months. The yearly LTS streams have an overlap of 6 months. The current version is Flatcar Container Linux 4081.3.10.

View as json feed: amd64 arm64
EC2 Region AMI Type AMI ID CloudFormation
af-south-1 HVM (amd64) ami-05a772026dc408647 Launch Stack
HVM (arm64) ami-0ad57968568723f36 Launch Stack
ap-east-1 HVM (amd64) ami-04d7fa0263e0ef32c Launch Stack
HVM (arm64) ami-05d5a6234065fed83 Launch Stack
ap-northeast-1 HVM (amd64) ami-08bf1545275007829 Launch Stack
HVM (arm64) ami-081c206fff05b2ab4 Launch Stack
ap-northeast-2 HVM (amd64) ami-0bf117d346059475a Launch Stack
HVM (arm64) ami-0a58bd57d4c26a4b8 Launch Stack
ap-south-1 HVM (amd64) ami-0573c47493f2b936f Launch Stack
HVM (arm64) ami-05f965b8e850473af Launch Stack
ap-southeast-1 HVM (amd64) ami-06c9f7b8a95d4bfcc Launch Stack
HVM (arm64) ami-087b458b5f9c7a947 Launch Stack
ap-southeast-2 HVM (amd64) ami-09fef94fdf395a30b Launch Stack
HVM (arm64) ami-0894358e267807efc Launch Stack
ap-southeast-3 HVM (amd64) ami-07f5d1d3ad36a957e Launch Stack
HVM (arm64) ami-07e776588b457884f Launch Stack
ca-central-1 HVM (amd64) ami-053eeb774f7b47f1a Launch Stack
HVM (arm64) ami-0d7b7dc1b01cd6c89 Launch Stack
eu-central-1 HVM (amd64) ami-0b9fd5fb68aef08e2 Launch Stack
HVM (arm64) ami-0bae44a763980f70b Launch Stack
eu-north-1 HVM (amd64) ami-09074e2edfa707bcf Launch Stack
HVM (arm64) ami-0da51dc73f170abf3 Launch Stack
eu-south-1 HVM (amd64) ami-0bbefa691d884d83f Launch Stack
HVM (arm64) ami-084d0ec6600d0ed8e Launch Stack
eu-west-1 HVM (amd64) ami-0494fac507784c086 Launch Stack
HVM (arm64) ami-02943c9d40df1758a Launch Stack
eu-west-2 HVM (amd64) ami-01f414cb9482584ac Launch Stack
HVM (arm64) ami-0051704190cc04abb Launch Stack
eu-west-3 HVM (amd64) ami-0b2e4e3936441fe67 Launch Stack
HVM (arm64) ami-029c73e52fe9e0ca1 Launch Stack
sa-east-1 HVM (amd64) ami-0a7945c9863fcaec1 Launch Stack
HVM (arm64) ami-0949ab9d4c718c138 Launch Stack
us-east-1 HVM (amd64) ami-0a27b808c8a598d4a Launch Stack
HVM (arm64) ami-0340500a0c3d02c80 Launch Stack
us-east-2 HVM (amd64) ami-03fe3ea4e5275a7f1 Launch Stack
HVM (arm64) ami-055f93d4caf55f95b Launch Stack
us-west-1 HVM (amd64) ami-092204f08e6792d0e Launch Stack
HVM (arm64) ami-0f0c022f51b67b551 Launch Stack
us-west-2 HVM (amd64) ami-07d5fdc793437c076 Launch Stack
HVM (arm64) ami-058e5875c45176be1 Launch Stack

Butane Configs

Flatcar Container Linux allows you to configure machine parameters, configure networking, launch systemd units on startup, and more via Butane Configs. These configs are then transpiled into Ignition configs and given to booting machines. Head over to the docs to learn about the supported features .

You can provide a raw Ignition JSON config to Flatcar Container Linux via the Amazon web console or via the EC2 API .

As an example, this Butane YAML config will start an NGINX Docker container:

variant: flatcar
version: 1.0.0
systemd:
  units:
    - name: nginx.service
      enabled: true
      contents: |
        [Unit]
        Description=NGINX example
        After=docker.service
        Requires=docker.service
        [Service]
        TimeoutStartSec=0
        ExecStartPre=-/usr/bin/docker rm --force nginx1
        ExecStart=/usr/bin/docker run --name nginx1 --pull always --log-driver=journald --net host docker.io/nginx:1
        ExecStop=/usr/bin/docker stop nginx1
        Restart=always
        RestartSec=5s
        [Install]
        WantedBy=multi-user.target

Transpile it to Ignition JSON:

cat cl.yaml | docker run --rm -i quay.io/coreos/butane:latest > ignition.json

Instance storage

Ephemeral disks and additional EBS volumes attached to instances can be mounted with a .mount unit. Amazon’s block storage devices are attached differently depending on the instance type . Here’s the Butane Config to format and mount the first ephemeral disk, xvdb, on most instance types:

variant: flatcar
version: 1.0.0
storage:
  filesystems:
    - device: /dev/xvdb
      format: ext4
      wipe_filesystem: true
      label: ephemeral
systemd:
  units:
    - name: media-ephemeral.mount
      enabled: true
      contents: |
        [Mount]
        What=/dev/disk/by-label/ephemeral
        Where=/media/ephemeral
        Type=ext4

        [Install]
        RequiredBy=local-fs.target

For more information about mounting storage, Amazon’s own documentation is the best source. You can also read about mounting storage on Flatcar Container Linux .

Adding more machines

To add more instances to the cluster, just launch more with the same Butane Config, the appropriate security group and the AMI for that region. New instances will join the cluster regardless of region if the security groups are configured correctly.

SSH to your instances

Flatcar Container Linux is set up to be a little more secure than other cloud images. By default, it uses the core user instead of root and doesn’t use a password for authentication. You’ll need to add an SSH key(s) via the AWS console or add keys/passwords via your Butane Config in order to log in.

To connect to an instance after it’s created, run:

ssh core@<ip address>

Multiple clusters

If you would like to create multiple clusters you will need to change the “Stack Name”. You can find the direct template file on S3 .

Manual setup

TL;DR: launch three instances of ami-03a4fafc6e446f063 (amd64) in us-east-1 with a security group that has open port 22, 2379, 2380, 4001, and 7001 and the same “User Data” of each host. SSH uses the core user and you have etcd and Docker to play with.

Creating the security group

You need open port 2379, 2380, 7001 and 4001 between servers in the etcd cluster. Step by step instructions below.

Note: This step is only needed once

First we need to create a security group to allow Flatcar Container Linux instances to communicate with one another.

  1. Go to the security group page in the EC2 console.
  2. Click “Create Security Group”
    • Name: flatcar-testing
    • Description: Flatcar Container Linux instances
    • VPC: No VPC
    • Click: “Yes, Create”
  3. In the details of the security group, click the Inbound tab
  4. First, create a security group rule for SSH
    • Create a new rule: SSH
    • Source: 0.0.0.0/0
    • Click: “Add Rule”
  5. Add two security group rules for etcd communication
    • Create a new rule: Custom TCP rule
    • Port range: 2379
    • Source: type “flatcar-testing” until your security group auto-completes. Should be something like “sg-8d4feabc”
    • Click: “Add Rule”
    • Repeat this process for port range 2380, 4001 and 7001 as well
  6. Click “Apply Rule Changes”

Launching a test cluster

We will be launching three instances, with a few parameters in the User Data, and selecting our security group.

  • Open the quick launch wizard to boot: Alpha ami-03a4fafc6e446f063 (amd64), Beta ami-0488e9d90d3be7a46 (amd64), or Stable ami-0fd55907279e3a71d (amd64)
  • On the second page of the wizard, launch 3 servers to test our clustering
    • Number of instances: 3, “Continue”
  • Paste your Ignition JSON config in the EC2 dashboard into the “User Data” field, “Continue”
  • Storage Configuration, “Continue”
  • Tags, “Continue”
  • Create Key Pair: Choose a key of your choice, it will be added in addition to the one in the gist, “Continue”
  • Choose one or more of your existing Security Groups: “flatcar-testing” as above, “Continue”
  • Launch!

Installation from a VMDK image

One of the possible ways of installation is to import the generated VMDK Flatcar image as a snapshot. The image file will be in https://${CHANNEL}.release.flatcar-linux.net/${ARCH}-usr/${VERSION}/flatcar_production_ami_vmdk_image.vmdk.bz2. Make sure you download the signature (it’s available in https://${CHANNEL}.release.flatcar-linux.net/${ARCH}-usr/${VERSION}/flatcar_production_ami_vmdk_image.vmdk.bz2.sig) and check it before proceeding.

$ wget https://alpha.release.flatcar-linux.net/amd64-usr/current/flatcar_production_ami_vmdk_image.vmdk.bz2
$ wget https://alpha.release.flatcar-linux.net/amd64-usr/current/flatcar_production_ami_vmdk_image.vmdk.bz2.sig
$ gpg --verify flatcar_production_ami_vmdk_image.vmdk.bz2.sig
gpg: assuming signed data in 'flatcar_production_ami_vmdk_image.vmdk.bz2'
gpg: Signature made Thu 15 Mar 2018 10:27:57 AM CET
gpg:                using RSA key A621F1DA96C93C639506832D603443A1D0FC498C
gpg: Good signature from "Flatcar Buildbot (Official Builds) <[email protected]>" [ultimate]

Then, follow the instructions in Importing a Disk as a Snapshot Using VM Import/Export . You’ll need to upload the uncompressed vmdk file to S3.

After the snapshot is imported, you can go to “Snapshots” in the EC2 dashboard, and generate an AMI image from it. To make it work, use /dev/sda2 as the “Root device name” and you probably want to select “Hardware-assisted virtualization” as “Virtualization type”.

Using Flatcar Container Linux

Now that you have a machine booted it is time to play around. Check out the Flatcar Container Linux Quickstart guide or dig into more specific topics .

Terraform

The aws Terraform Provider allows to deploy machines in a declarative way. Read more about using Terraform and Flatcar here .

The following Terraform v0.13 module may serve as a base for your own setup. It will also take care of registering your SSH key at AWS EC2 and managing the network environment with Terraform.

You can clone the setup from the Flatcar Terraform examples repository or create the files manually as we go through them and explain each one.

git clone https://github.com/flatcar/flatcar-terraform.git
# From here on you could directly run it, TLDR:
cd aws
export AWS_ACCESS_KEY_ID=...
export AWS_SECRET_ACCESS_KEY=...
terraform init
# Edit the server configs or just go ahead with the default example
terraform plan
terraform apply

Start with a aws-ec2-machines.tf file that contains the main declarations:

terraform {
  required_version = ">= 0.13"
  required_providers {
    ct = {
      source  = "poseidon/ct"
      version = "0.7.1"
    }
    template = {
      source  = "hashicorp/template"
      version = "~> 2.2.0"
    }
    null = {
      source  = "hashicorp/null"
      version = "~> 3.0.0"
    }
    aws = {
      source  = "hashicorp/aws"
      version = "~> 3.19.0"
    }
  }
}

provider "aws" {
  region = var.aws_region
}

resource "aws_vpc" "network" {
  cidr_block = var.vpc_cidr

  tags = {
    Name = var.cluster_name
  }
}

resource "aws_subnet" "subnet" {
  vpc_id     = aws_vpc.network.id
  cidr_block = var.subnet_cidr

  tags = {
    Name = var.cluster_name
  }
}

resource "aws_internet_gateway" "gateway" {
  vpc_id = aws_vpc.network.id

  tags = {
    Name = var.cluster_name
  }
}

resource "aws_route_table" "default" {
  vpc_id = aws_vpc.network.id

  route {
    cidr_block = "0.0.0.0/0"
    gateway_id = aws_internet_gateway.gateway.id
  }

  tags = {
    Name = var.cluster_name
  }
}

resource "aws_route_table_association" "public" {
  route_table_id = aws_route_table.default.id
  subnet_id      = aws_subnet.subnet.id
}

resource "aws_security_group" "securitygroup" {
  vpc_id = aws_vpc.network.id

  tags = {
    Name = var.cluster_name
  }
}

resource "aws_security_group_rule" "outgoing_any" {
  security_group_id = aws_security_group.securitygroup.id
  type              = "egress"
  from_port         = 0
  to_port           = 0
  protocol          = "-1"
  cidr_blocks       = ["0.0.0.0/0"]
}

resource "aws_security_group_rule" "incoming_any" {
  security_group_id = aws_security_group.securitygroup.id
  type              = "ingress"
  from_port         = 0
  to_port           = 0
  protocol          = "-1"
  cidr_blocks       = ["0.0.0.0/0"]
}

resource "aws_key_pair" "ssh" {
  key_name   = var.cluster_name
  public_key = var.ssh_keys.0
}

data "aws_ami" "flatcar_stable_latest" {
  most_recent = true
  owners      = ["aws-marketplace"]

  filter {
    name   = "architecture"
    values = ["x86_64"]
  }

  filter {
    name   = "virtualization-type"
    values = ["hvm"]
  }

  filter {
    name   = "name"
    values = ["Flatcar-stable-*"]
  }
}

resource "aws_instance" "machine" {
  for_each      = toset(var.machines)
  instance_type = var.instance_type
  user_data     = data.ct_config.machine-ignitions[each.key].rendered
  ami           = data.aws_ami.flatcar_stable_latest.image_id
  key_name      = aws_key_pair.ssh.key_name

  associate_public_ip_address = true
  subnet_id                   = aws_subnet.subnet.id
  vpc_security_group_ids      = [aws_security_group.securitygroup.id]

  tags = {
    Name = "${var.cluster_name}-${each.key}"
  }
}

data "ct_config" "machine-ignitions" {
  for_each = toset(var.machines)
  content  = data.template_file.machine-configs[each.key].rendered
}

data "template_file" "machine-configs" {
  for_each = toset(var.machines)
  template = file("${path.module}/cl/machine-${each.key}.yaml.tmpl")

  vars = {
    ssh_keys = jsonencode(var.ssh_keys)
    name     = each.key
  }
}

Create a variables.tf file that declares the variables used above:

variable "machines" {
  type        = list(string)
  description = "Machine names, corresponding to cl/machine-NAME.yaml.tmpl files"
}

variable "cluster_name" {
  type        = string
  description = "Cluster name used as prefix for the machine names"
}

variable "ssh_keys" {
  type        = list(string)
  description = "SSH public keys for user 'core'"
}

variable "aws_region" {
  type        = string
  default     = "us-east-2"
  description = "AWS Region to use for running the machine"
}

variable "instance_type" {
  type        = string
  default     = "t3.medium"
  description = "Instance type for the machine"
}

variable "vpc_cidr" {
  type    = string
  default = "172.16.0.0/16"
}

variable "subnet_cidr" {
  type    = string
  default = "172.16.10.0/24"
}

An outputs.tf file shows the resulting IP addresses:

output "ip-addresses" {
  value = {
    for key in var.machines :
    "${var.cluster_name}-${key}" => aws_instance.machine[key].public_ip
  }
}

Now you can use the module by declaring the variables and a Container Linux Configuration for a machine. First create a terraform.tfvars file with your settings:

cluster_name           = "mycluster"
machines               = ["mynode"]
ssh_keys               = ["ssh-rsa AA... [email protected]"]

The machine name listed in the machines variable is used to retrieve the corresponding Container Linux Config . For each machine in the list, you should have a machine-NAME.yaml.tmpl file with a corresponding name.

For example, create the configuration for mynode in the file machine-mynode.yaml.tmpl (The SSH key used there is not really necessary since we already set it as VM attribute):

---
passwd:
  users:
    - name: core
      ssh_authorized_keys:
        - ${ssh_keys}
storage:
  files:
    - path: /home/core/works
      filesystem: root
      mode: 0755
      contents:
        inline: |
          #!/bin/bash
          set -euo pipefail
           # This script demonstrates how templating and variable substitution works when using Terraform templates for Container Linux Configs.
          hostname="$(hostname)"
          echo My name is ${name} and the hostname is $${hostname}

Finally, run Terraform v0.13 as follows to create the machine:

export AWS_ACCESS_KEY_ID=...
export AWS_SECRET_ACCESS_KEY=...
terraform init
terraform apply

Log in via ssh core@IPADDRESS with the printed IP address (maybe add -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null).

When you make a change to machine-mynode.yaml.tmpl and run terraform apply again, the machine will be replaced.

You can find this Terraform module in the repository for Flatcar Terraform examples .